CVE-2021-31950: high-severity vulnerability in Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server Spoofing Vulnerability
Published · Updated
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.6epss 4.6%
from disclosure to weapon3 days
Published on NVDJun 8
1st PoC+3d
exploitation probability
4.6%top 9% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Microsoft SharePoint Server Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft SharePoint Enterprise Server 2016Microsoft · Microsoft SharePoint Foundation 2013 Service Pack 1Microsoft · Microsoft SharePoint Server 2019public PoCs found — 2
exploitdbwww.exploit-db.com/exploits/49982unverifiedcve_referencepacketstormsecurity.com/files/163080/Microsoft-SharePoint-Server-16.0.10372.20060-Server-Side-Request-Forgery.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Microsoft SharePoint Enterprise Server 2016
In the same product, most dangerous first.
CVE-2025-53770CRITICALMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 100.0%KEVCVE-2025-49704HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 100.0%KEVCVE-2023-29357CRITICALMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 100.0%KEVCVE-2025-49706MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 99.1%KEVCVE-2023-24955HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 85.0%KEVCVE-2026-55040CRITICALMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 69.5%KEV